Home
MEDIUM: 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HDefault status
unaffected
4.6.0 (semver) before 4.6.5
affected
4.4.9 (semver) before 4.4.15
affected
Description
Dissection engine LZ77 decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Problem types
CWE-1325: Improperly Controlled Sequential Memory Allocation
Product status
4.6.0 (semver) before 4.6.5
4.4.9 (semver) before 4.4.15
Credits
Sharon Brizinov
References
gitlab.com/wireshark/wireshark/-/work_items/21127
www.wireshark.org/security/wnpa-sec-2026-28.html
gitlab.com/wireshark/wireshark/-/issues/21127 (GitLab Issue #21127)